
Wbcom Designs – Custom Font Uploader Security & Risk Analysis
wordpress.org/plugins/custom-font-uploaderDescription Enhance site typography easily with Google and custom fonts. You don't need an API; you can host fonts locally.
Is Wbcom Designs – Custom Font Uploader Safe to Use in 2026?
Generally Safe
Score 91/100Wbcom Designs – Custom Font Uploader has a strong security track record. Known vulnerabilities have been patched promptly.
The 'custom-font-uploader' plugin v2.4.0 exhibits a generally strong security posture in its current state based on the provided static analysis. The absence of critical or high-severity taint flows, coupled with a high percentage of properly escaped output and the exclusive use of prepared statements for SQL queries, are significant strengths. Furthermore, all identified entry points (AJAX handlers, REST API routes, shortcodes) appear to have authentication checks implemented, and there are a healthy number of nonce and capability checks. This suggests a conscious effort by the developers to implement secure coding practices.
However, the plugin's vulnerability history is a notable concern. It has a history of two medium-severity CVEs, with the most recent one dated June 5, 2024, and it was listed as unpatched at that time. While currently there are no unpatched vulnerabilities, this past pattern, particularly involving missing authorization, warrants caution. It suggests that while the plugin has been improved, there's a recurring tendency for authorization issues to arise. The presence of a bundled, potentially outdated library (Select2 v3.5.3) also presents a minor risk, as older versions of libraries can contain undiscovered vulnerabilities.
In conclusion, 'custom-font-uploader' v2.4.0 has made substantial improvements in secure coding. The static analysis reveals a robust implementation of security checks. Nevertheless, the historical pattern of medium-severity vulnerabilities, particularly those related to authorization, should not be overlooked. Users should remain vigilant and ensure they are always running the latest patched version when it becomes available, as past issues suggest a potential for them to re-emerge if not meticulously addressed.
Key Concerns
- Bundled outdated library: Select2 v3.5.3
- History of medium severity CVEs (2 total)
Wbcom Designs – Custom Font Uploader Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Wbcom Designs - Custom Font Uploader <= 2.3.4 - Missing Authorization to Font Deletion
Wbcom Designs Plugins (Various Versions) - Arbitrary Plugin Installation, Activation and Deactivation
Wbcom Designs – Custom Font Uploader Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Wbcom Designs – Custom Font Uploader Attack Surface
AJAX Handlers 5
Shortcodes 1
WordPress Hooks 23
Maintenance & Trust
Wbcom Designs – Custom Font Uploader Maintenance & Trust
Maintenance Signals
Community Trust
Wbcom Designs – Custom Font Uploader Alternatives
Fonts Plugin | Use Google Fonts, Adobe Fonts or Upload Fonts
olympus-google-fonts
The easiest to customize fonts in WordPress. Optimized for Speed. 1000+ font choices. Supports Google Fonts, Adobe Fonts and Upload Fonts.
Local Fonts Uploader – Upload & Host Any Font Locally for GDPR
local-fonts-uploader
Easily upload and host fonts locally. Avoid external requests to enhance security, privacy, speed, and GDPR compliance.
Custom Fonts – Host Your Fonts Locally
custom-fonts
Custom Fonts is a powerful WordPress plugin that allows you to upload your own custom fonts or choose from a vast collection of Google Fonts, all host …
Use Any Font | Custom Font Uploader
use-any-font
Upload custom fonts with custom font uploader. Auto converts to woff2 for better performance. Self-hosted, GDPR compliant, and easy custom font plugin
Fonts
fonts
Add More Font To Your WordPress Editor
Wbcom Designs – Custom Font Uploader Developer Profile
19 plugins · 10K total installs
How We Detect Wbcom Designs – Custom Font Uploader
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-font-uploader/assets/css/cfup-custom-font.css/wp-content/plugins/custom-font-uploader/assets/js/cfup-admin.js/wp-content/plugins/custom-font-uploader/assets/js/cfup-custom-font.js/wp-content/plugins/custom-font-uploader/assets/js/cfup-admin.js/wp-content/plugins/custom-font-uploader/assets/js/cfup-custom-font.jscustom-font-uploader/assets/css/cfup-custom-font.css?ver=custom-font-uploader/assets/js/cfup-admin.js?ver=custom-font-uploader/assets/js/cfup-custom-font.js?ver=HTML / DOM Fingerprints
cfup-add-font-wrappercfup-custom-fonts-wrapcfup-google-font-wrapcfup-font-namecfup-font-style-labelcfup-font-stylecfup-font-variants-labelcfup-font-variants+21 more<!-- Custom Font Uploader --><!-- End Custom Font Uploader --><!-- Wbcom Designs Admin Settings --><!-- End Wbcom Designs Admin Settings -->+2 moredata-cfup-font-namedata-cfup-font-familydata-cfup-font-styledata-cfup-font-weightdata-cfup-font-upload-urldata-cfup-google-font-family+1 morecfup_ajax_object[wbcom_admin_setting_header]